== Tag == 8 releases
security
Releases that exist because of this tag, or that had to change when it did.
Every release here fixed something exploitable, or closed a gap before it became one. Dates are the release date, not the disclosure date.
- accessibility 36
- performance 28
- seo 23
- admin-ui 21
- media 20
- block-editor 16
- tooling 13
- i18n 12
- wp-cli 12
- privacy 12
- patterns 12
- typography 10
- migration 8
- security 8
- caching 8
- multisite 7
- rest-api 7
- editorial 6
- theme-json 6
- email 5
- woocommerce 5
- cron 4
- gdpr 3
- dark-mode 3
- breaking 3
- forms 2
- revisions 2
- php-8 1
- Everything 100
= 1.6.0 =
Bastion
High-traffic resilience theme: cacheable to the edge, degrades to static, and holds up when the origin is under load.
Themes 1,800+
= 3.3.0 =
Bailiwick
Role and capability editor with an impact preview, an audit log, and an export to PHP for version control.
Plugins 17,000+
= 1.8.0 =
Rampart
B2B security company theme: no third-party requests, strict CSP compatible, and a disclosure page pattern.
Themes 1,100+
= 1.2.0 =
Passkey Post
WebAuthn passkey login for WordPress, with per-role enforcement and a recovery path that does not go through email.
Plugins 9,600+
= 1.5.0 =
Rasp
Bulk HTML cleanup for imported content: strips editor cruft, converts to blocks, and previews every change before applying.
Plugins 5,800+
= 1.5.0 =
Stint
Session management: list active sessions per user, end them individually, and set idle and absolute limits per role.
Plugins 8,200+
= 2.6.0 =
Hasp
TOTP two-factor with staged rollout, per-role enforcement, grace periods, and recovery an administrator can grant.
Plugins 21,000+
= 2.2.0 =
Sentinel Headers
Content Security Policy and friends, with a report-only mode that tells you what would have broken before you enforce anything.
Plugins 5,400+